FirmSideAINonprofit AI Academy | W02

W02 90 minSelf-paced

Data, privacy, security, and records

Most AI harm in nonprofit work is not exotic. It is a piece of information going somewhere it should not, or a record no one can reconstruct later. This module gives you a working sense of the information you handle, the rules that govern it, the difference between privacy and security, and the habit of leaving a trace. These are the daily decisions that protect the people you serve.

By the end, you will be able to

  • Recognize the kinds of information you handle and how sensitive each is.
  • Ask what authority and purpose allow you to use a piece of information.
  • Tell privacy apart from cybersecurity, and give each its own care.
  • Keep a record of what was used, checked, approved, and kept.

Lesson 1

Know the information

Not all information carries the same weight. The first skill is recognizing what kind you are holding before you do anything with it.

Nonprofit work runs on many kinds of information, and they are not equally sensitive. A published event flyer and a person's case notes are both information, but they call for very different care. Naming the kind is the first move, every time.

These are the kinds you are most likely to touch:

  • Donor data: who gives, how much, and their contact details.
  • Employee data: staff records, pay, and personal details.
  • Volunteer data: contact information and background details.
  • Beneficiary data: information about the people you serve.
  • Education data: student records, often about minors.
  • Health and disability data: sensitive by nature and often specially protected.
  • Financial data: accounts, transactions, and payment details.
  • Case data: detailed notes about a person's situation.
  • Organizational data: internal plans, strategy, and undecided matters.

Important

Health, disability, education, and case data about a real person are the most sensitive, and the most damaging if exposed. When any of these are in front of you, slow down before it goes anywhere near a tool.

Try it

List the kinds of information you personally handle in a normal week. Circle the two most sensitive. Those are the ones to be most careful with.

RememberName the kind of information before you act. The most sensitive kinds deserve the most care.

Lesson 2

Know the authority and purpose

Having information is not the same as being allowed to use it however you like. Ask what permits this use, and for what.

Every piece of information came with strings attached, even when they are invisible. Someone consented to a specific use. A contract or a funder set rules. A policy said who may see it and for how long. Using information outside those bounds can break trust or an agreement, even when no one meant harm.

Before you use information, ask what governs it:

  • Consent: did the person agree to this use, or only to another one?
  • Contracts: does an agreement with a vendor or partner restrict it?
  • Funder rules: does a grant or funder set conditions on this data?
  • Policy: what does your organization's own policy allow?
  • Retention: how long are you allowed to keep it?
  • Access: who is actually permitted to see it?

Who decides

These labels come from different places: some are law or contract, some are policy, and some are just good practice. Some are set by law you cannot consent your way around, like HIPAA for health data, FERPA for student records, and state privacy and breach rules. When you are unsure a use is allowed, that uncertainty is itself the signal to check with someone who has the authority to say yes.

Try it

Pick one piece of information you use often. Say, in a sentence, what allows you to use it: consent, a contract, a funder rule, or policy. If you cannot say, that is worth asking about.

RememberHolding information is not permission to use it. Consent, contracts, funder rules, and policy set the bounds.

Lesson 3

Privacy is not the same as cybersecurity

These two words get blurred together, but they protect different things. You need both, and they are not interchangeable.

Privacy is about the information itself: collecting only what you need, using it only for the reason you gathered it, and not spreading it further than necessary. It is a question of restraint and purpose.

Cybersecurity is about protecting your accounts and systems: strong passwords, locked accounts, careful attention to suspicious messages, and keeping intruders out. It is a question of defense.

Why you need both

You can have strong security and still harm someone's privacy, by pasting their case details into a tool that did not need them. And you can respect privacy in intent but still expose data through a weak password on the account that holds it. One does not cover for the other.

Note

A simple way to hold it: privacy asks should this information be here at all, and how much of it. Security asks is this account and system locked down. They are not independent, though, because you cannot keep a privacy promise if the account holding the data is not secured. Security is the floor privacy stands on, so do both.

Try it

Think of one recent task. Name one privacy decision in it (should this data be used here at all?) and one security decision (is this account protected?). Notice they are two different questions.

RememberPrivacy governs the data itself. Security protects the accounts and systems. You need both, separately.

Lesson 4

Records and traceability

If a decision or an output ever gets questioned, you want to reconstruct what happened. That means leaving a trace as you go.

When AI helps with real work, someone may later need to know what happened: a funder, a colleague, an affected person, or you in six months. A record makes that possible. Without one, an AI-supported result is a mystery, and a mystery is hard to defend or fix.

A useful record captures the simple facts of what was done:

  • Used: what information you put into the tool.
  • Generated: what the tool produced.
  • Checked: how you verified it, and what you found.
  • Approved: who reviewed and signed off before it went out.
  • Retained: what you kept, and where.
  • Disclosed: whether the use of AI was made clear to anyone who should know.

Who decides

This does not have to be heavy. A few notes attached to the work are usually enough. The goal is that a reasonable person could later understand what was used, what was checked, and who was responsible.

Try it

For one AI-supported task, jot the six lines: used, generated, checked, approved, retained, disclosed. Notice how little time it takes and how much it would help later.

RememberLeave a trace: what was used, generated, checked, approved, retained, and disclosed.

Lesson 5

When something goes wrong

Even careful people hit incidents. What matters is recognizing one and knowing your first move, before the pressure of the moment.

An incident is not always dramatic. It can be a piece of data pasted into the wrong tool, a suspicious message pretending to be a colleague, a fake voice or image asking for something, or someone using a tool no one reviewed. The skill is spotting these for what they are and responding calmly.

Learn to recognize the common ones:

  • Data exposure: sensitive information went somewhere it should not have.
  • Phishing: a message trying to trick you into a click, a login, or a payment.
  • Synthetic impersonation: a fake voice, image, or message posing as a real person.
  • Unauthorized tool use: someone handling real data in a tool no one approved.

The first response is a short sequence you can run under pressure: recognize it, stop, and do not act further. Then preserve it, without deleting or fixing it yourself, and report it through your organization's trusted route. Speed helps, but a calm, correct report helps more.

Important

Pressure to act fast and quietly is a warning sign, not a reason to skip the process. Do not try to quietly clean it up, because deleting the message or the data can destroy the record your organization needs to respond. Slow down and report through a channel you already trust. And if your organization has no incident route, that gap is itself worth raising, because someone should own this before an incident, not during one.

Try it

Say the first-response sequence from memory: recognize, stop, preserve, report. Then name who you would actually report an incident to at your organization. If you do not know, find out this week.

RememberIncidents happen to careful people too. Recognize, stop, preserve the evidence, and report through a trusted route.

What you leave with

Role-specific safe-input matrix and incident route

A page tailored to your own role: which kinds of information you handle, what may go into which tools, and the exact steps and contact for reporting an incident. It turns the whole module into something you can keep at your desk and act on without having to remember it all.

This is just for you. It saves on this device only, and nothing is scored.